cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
773
Views
0
Helpful
6
Replies

ISE LDAP Communication to Secondary AD

Rob4
Cisco Employee
Cisco Employee

Hi All,

 

I have a customer that connects their ISE deployment to their main Active Directory Domain. They are seeing traffic from a PSN to a secondary Active Directory domain that has a one-way trust with the main Active Directory domain. 

 

Is there any reason there would be traffic to the secondary domain if its not specified in the config? The secondary domain is not listed in the secondary domains for the ISE deployment. 

 

Appreciate any guidance. 

 

Thanks,

 

Rob 

2 Accepted Solutions

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

Such traffic is for AD domain and forest discovery.

View solution in original post

Rob4
Cisco Employee
Cisco Employee

Thanks for the reply. So, if there was no trusting between the two domains, would we see that discovery still? 

 

 

Thanks,

 

Rob 

View solution in original post

6 Replies 6

hslai
Cisco Employee
Cisco Employee

Such traffic is for AD domain and forest discovery.

Rob4
Cisco Employee
Cisco Employee

Thanks for the reply. So, if there was no trusting between the two domains, would we see that discovery still? 

 

 

Thanks,

 

Rob 

hslai
Cisco Employee
Cisco Employee

Yes.

Rob4
Cisco Employee
Cisco Employee

Thanks for the assistance. Do we have any documentation to show this behavior? The customer will need to provide some info to other team members. 

 

 

Thanks,

 

Rob 

Nidhi
Cisco Employee
Cisco Employee

I suggest going through Cisco Live session - BRKSEC-2132 which has information about discovery !

Thanks,

Nidhi 

Rob4
Cisco Employee
Cisco Employee

Thanks so much for the info!